SafeVault

Document Security

Client Portals for Accountants: How to Choose a Secure One Before Tax Season

Client Portals for Accountants: How to Choose a Secure One Before Tax Season

Short answer: A client portal for accountants is a secure, permissioned place where your firm requests, receives and shares client documents instead of using email. A good one gives each client access to only their own files, tracks every document request with a status, encrypts documents in transit and at rest, and records document activity. For tax and accounting firms it also supports, but does not replace, your obligations under the FTC Safeguards Rule.

This article is general information, not legal or compliance advice.

Every accounting firm knows the March conversation. Someone asks a client for a missing 1099. The client says they sent it. Both are right: it went to a different person, attached to an email about something else, six weeks ago.

The cost is not the search. It is that nobody can see the state of the work. A preparer cannot tell what is outstanding without opening their inbox. A reviewer cannot tell whether the file is complete. The client, who did everything asked of them, cannot tell either.

A client portal fixes that by making the request itself the unit of work.

Why accounting firms move to a client portal

Three things push most firms to switch.

Follow-up volume. In busy season, a large share of client email is reassurance: "Did you get my W-2?" When clients can see their own list of outstanding items, much of that traffic disappears. We looked at this in more detail in why CPA teams struggle during tax season.

Sensitive data in the wrong places. Tax returns, Social Security numbers and bank statements sitting in email threads are hard to protect and harder to clean up.

Security obligations. Tax and accounting practices have specific federal duties around customer information, covered below. A portal is one of the most practical ways to show you are meeting them.

Your security obligations, in plain terms

The FTC Safeguards Rule

Under the Gramm-Leach-Bliley Act, the Federal Trade Commission treats tax preparers and many accounting practices as financial institutions. That brings them under the FTC Safeguards Rule, which requires a written information security program to protect customer information.

The FTC's guidance lists the elements the program should include. Among them: designating a qualified individual to run the program, assessing risks, limiting who can access customer information, encrypting customer information in transit and at rest, using multi-factor authentication for people accessing it, training staff, overseeing service providers, and having an incident response plan.

The IRS guidance

The IRS publishes two documents most firms should keep at hand. Publication 4557, Safeguarding Taxpayer Data, explains the safeguards expected of tax professionals. Publication 5708 walks through creating a Written Information Security Plan (WISP) for a tax and accounting practice.

Where a portal fits

A secure client portal helps with several of these elements at once: it limits access to named people, encrypts documents, and keeps a record of document activity. It does not write your WISP, train your staff or run your risk assessment. Treat it as one control inside your program, not as the program itself.

What a secure client portal for accountants should include

Document requests with a status

This matters more than anything else on the list. Instead of an email asking for five documents, you send a request. The client sees exactly what you need and uploads against it. You see what has arrived, what is missing and how long it has been waiting.

One client, one set of documents

Each client should see only their own files. Access should be granted to named people, such as a married couple filing jointly, and withdrawn when the engagement closes, without deleting your firm's records.

Encryption in transit and at rest

Documents should be encrypted while they travel (TLS) and while they are stored. Ask which parts are covered: the database, the stored files and the backups. The Safeguards Rule calls for encryption of customer information both ways, so this question matters.

An activity log

You should be able to see what was done to a document: uploaded, shared, renamed, deleted. Ask how far back the log goes and whether it records views or only actions.

Simple team roles

Most firms need clear owner and staff roles, plus the ability to share a specific document with a specific person. Complex permission matrices tend to go unused.

Sorting on arrival

Clients upload files named IMG_4417.jpg. A portal that classifies documents and extracts key fields as they arrive saves your team a sorting pass on every return.

Nothing for clients to install

If clients need an app or a complex login, some will email documents anyway. Browser-based upload through an invitation keeps adoption high.

Rolling out a portal before busy season

Timing matters. Introducing a new tool in February adds friction exactly when you have none to spare.

  1. Choose and set up in the autumn. Test it yourself with sample data first.
  2. Pilot with a handful of friendly clients. Fix the confusing parts of your invitation before the full rollout.
  3. Build request templates. Create standard lists for common engagements, such as an individual return or a small-business return.
  4. Invite all clients in December or early January. Explain why in one sentence: "So your tax documents are not sitting in email."
  5. Stop accepting sensitive documents by email. Politely redirect clients to the portal, every time.
  6. Close the season cleanly. Withdraw access for completed engagements and review your activity log.

Questions to ask before you choose

  1. Does every document request carry a status the client can see?
  2. Is any document ever shared by open link?
  3. What exactly is encrypted at rest?
  4. Is multi-factor authentication available, and where is it required?
  5. Has the vendor completed an independent examination such as a SOC 2 Type 2, and can we read the report under an NDA?
  6. What does the activity log record, and for how long?
  7. Can clients upload from a browser without installing anything?
  8. What happens to access and documents when an engagement ends?
  9. If we receive health information from clients, is the tool HIPAA compliant? Most document portals are not.

For a wider comparison across professions, see our guide to the best client portal software.

Where SafeVault and TaxFlo fit

SafeVault's provider workspace is built for tax and accounting practices.

  • Document requests carry a status, so you and your client can see what is outstanding.
  • Each client sees only their own documents. Access is granted to named people and withdrawn when the work closes.
  • Documents are encrypted in transit using TLS and at rest using AES-256.
  • Uploads, shares, renames, deletions and other document actions are recorded in an activity log inside the product.
  • DocIQ classifies uploaded documents and extracts key fields, so files arrive sorted.
  • Teams use owner and staff roles, and multi-factor authentication is required for access to critical systems.
  • Clients upload through a browser. There is nothing to install.

Firms doing tax preparation can use TaxFlo, a dedicated tax workflow delivered through the same provider workspace. It handles client engagements, tax profiles, document requests and guided questionnaires, with billing built in.

AmitaSoft, LLC, which builds SafeVault and TaxFlo, completed a SOC 2 Type 2 examination covering Security, Availability, Processing Integrity and Confidentiality. The report is available under an NDA. See our security page for detail.

Two limits to know: SafeVault is not zero-knowledge, because DocIQ reads documents to classify them. And it is not HIPAA compliant, so it should not be used to store protected health information.

Key takeaways

  • The most valuable portal feature for accountants is a document request with a status that both sides can see.
  • Look for named, revocable access; encryption in transit and at rest; an activity log; simple roles; and no-install uploads.
  • The FTC Safeguards Rule requires tax and accounting practices to run a written information security program. A portal supports it but does not replace it.
  • Keep IRS Publications 4557 and 5708 on hand when writing or reviewing your WISP.
  • Roll out before busy season, not during it.

Frequently asked questions

What is a client portal for accountants?

It is a secure, permissioned space where an accounting firm requests, receives and shares client documents. Each client sees only their own files, and the firm can track which requested documents have arrived.

Do accountants need a secure client portal?

There is no rule that names a specific tool, but the FTC Safeguards Rule requires tax and accounting practices to protect customer information, including encrypting it and limiting access. A secure client portal is one of the most practical ways to do that for documents.

Is a client portal required by the FTC Safeguards Rule?

No. The rule requires a written information security program with specific elements, such as access controls, encryption and multi-factor authentication. A portal can help meet several of them, but it is not required by name and does not satisfy the rule on its own.

What is a WISP for a tax practice?

A Written Information Security Plan describes how a practice protects client information. IRS Publication 5708 explains how to create one for a tax and accounting practice.

How do I get clients to actually use a client portal?

Pick a tool that works in a browser with nothing to install, send a short invitation explaining why, use clear document requests, and stop accepting sensitive documents by email once the portal is live.

This article is general information, not legal or compliance advice.

Explore SafeVault